Posts

Showing posts with the label Sandrorat

How to check for a root access in three ways (plus a C&C demo!)

Image
Recently I have found a sample of DroidJack, which is somehow the same as Sandrorat described previously . Well, it is probably created by the same author or at least on the same code base. What leads me to that conclusion? Well, see it for yourself in the screenshot below. How does the DroidJack C&C look like? I've found this little GIF demo in one of the DroidJack ads (if you haven't seen it already this means that you don't follow me on Twitter and you should ): So, the pretty much standard stuff for the more complex Android malware: you can do everything and get a "binder" i.e. program that lets you add DroidJack "features" to the benign apps. What else did the author of DroidJack and Sandrorat made? This app available in Play Store that is a kind of Sandrorat in reverse  - you can use a mobile phone to "control" your computer. Checking for root in three ways Enough about the authors, let's go to the main po...

Sandroid RAT analysis: Part I - synthetic communication

Image
My first post is about Sandrorat, a fairly new RAT tool that was prominent for being a part of a Polish spam campaign . The analyzed sample hash is bed05d8eace6a7ebc5dec7141ea4b9cc559f1b2aab8848e2c79df7a79de39b9d . Sample was obtained thanks to The Honeynet Project . Everything is synthetic First part will be about a little known synthetic methods and the way Sandrorat uses them to obfuscate the code . This sample declared three different services: